peter bassill · operator
$ curl https://example.co.uk/.well-known/security.txt

security.txt.

Check a disclosure policy, or generate one that validates against RFC 9116.

Reads the published file only. Or skip down to the generator to build one.

$ gen security.txt
Generate

Build a valid one.

A contact and an expiry are all it needs. Out comes a file that validates, and the snippets to serve and sign it.

Method

The checker validates against RFC 9116: Contact and Expires are required, Expires must be a future date within about a year, and Canonical, where present, should name the URL the file is served from. Where the file carries a PGP cleartext signature and this server holds the signer’s key, the signature is verified; otherwise it is reported as present but unverified — this tool does not reach out to fetch keys.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  cve